Cisco’s ASA 5500 and PIX 500 series security appliances provide integrated firewall, VPN, and intrusion prevention (IPS) services in economical single-box packages offering a broad spectrum of capabilities that meet the security needs of organizations ranging from small and mid-size businesses to enterprises and Internet service providers. Cisco’s ASA 5500 and PIX firewall products allow IT organizations to defend their network perimeter and achieve secure remote access while utilizing familiar management tools based on a common software foundation.

Because the ASA 5500 family of firewalls are built on the same software architecture as the discontinued PIX 500 security appliances, IT managers responsible for upgrading from PIX to ASA 5500 devices can get up to speed quickly as they deploy, manage, and maintain the new generation of Cisco products. Progent's Cisco-certified CCIE network engineers can help you manage your existing PIX 500 firewalls, migrate to ASA 5500 systems, and support any mix of ASA 5500 and PIX 500 firewalls via ultra-efficient remote consulting and troubleshooting services.

Cisco ASA 5500 Series Adaptive Security Appliances
Cisco’s ASA 5500 Series multi-function firewalls improve on the discontinued PIX 500 family they are designed to replace by introducing a modular hardware and software architecture for easy expansion and investment protection, offering optional Secure Sockets Layer (SSL) VPN support in addition to the standard IPsec VPN included with all models, and delivering substantially higher performance.

>Cisco ASA 5500 Consulting Support and Troubleshooting
The expandable design of the ASA 5500 Series allows you to add services by installing security service modules (SSMs) and security service cards (SSCs). These user-installable enhancements give you the option of adding IPS and content protection services such as blocking viruses, spyware, and phishing attacks and performing file and URL filtering. In addition to allowing you to respond quickly to new threat environments, the expandable design of the ASA 5500 Series also protects your capital investment by increasing the useful life of your security appliances. The ASA 5500 Series also protects your investment in IT staff training by supporting the rich set of PIX 500 management tools and protocols including the Cisco Adaptive Security Device Manager (ASDM) system for web-based management, secure command-line interface (CLI) access, verbose syslog, and SNMP.

Cisco ASA 5500 firewalls provide enhanced application protection via application-aware inspection processes that analyze network flows at Layers 4-7 and covers web, voice, and mobile wireless connectivity. Cisco's inspection engines integrate extensive application and protocol databases and employ advanced security enforcement technologies such as anomaly detection and application and protocol state monitoring. Cisco ASA firewall inspection engines also let you control IM and peer-to-peer file sharing so you can police usage policies and free up bandwidth for key business applications.

Cisco ASA 5505 Firewalls
Cisco ASA 5505 Firewall ConsultantsCisco's ASA 5505 firewall is designed for small businesses, branch offices, and enterprise teleworkers. These devices offer maximum firewall throughput of 150 Mbps and can handle up to 25 SSL VPN sessions plus 10,000 connections in the Base version and up to 25,000 connections in the Security Plus version. The ASA 5505 includes 256 MB of memory and can support up to three VLANs with trunking disabled. GTP/GPRS inspection, VPN clustering, and load balancing are not available in this entry-level firewall. High availability support is an option with the Security Plus version.

The ASA 5505 has a single expansion slot for a Security Services Card (SSC) that supports Advanced Inspection and Prevention. Maximum IPS throughput with this card installed is 75 Mbps.

Cisco ASA 5510, 5520, and 5540 Firewalls
Cisco ASA 5510, 5520, and 5540 Firewalls Integration HelpCisco's ASA 5510 firewall is designed for small and mid-sized businesses and small enterprises. The ASA 5510 offers maximum firewall throughput of 300 Mbps and can handle up to 250 SSL VPN sessions. In the Base version, the ASA 5510 supports 50,000 connections in the Base version and up to 130,000 connections in the Security Plus version. The ASA 5510 includes 256 MB of memory and can support up to 50 VLANs in the base version and 100 VLANs with the Security Plus version. Load balancing, VPN clustering, and high availability support are available only in the Security Plus version.

Cisco's ASA 5520 security appliance is designed for small enterprises. The 5510 offers maximum firewall throughput of 450 Mbps and can handle up to 750 SSL VPN sessions and 280,000 connections. The ASA 5520 includes 512 MB of memory and can support up to 150 VLANs. GTP/GPRS inspection, VPN clustering, plus support for load balancing and high availability are included.

Cisco's ASA 5540 is made for medium-sized enterprises, offers maximum firewall throughput of 650 Mbps, and can handle up to 2,500 SSL VPN sessions along with 400,000 connections. The ASA 5540 includes 1 GB of memory and can support up to 200 VLANs. GTP/GPRS inspection, VPN clustering, load balancing, and high availability support are included.

Cisco ASA 5510, 5520, and 5540 firewalls can each accept a single Security Services Module (SSM) that can support Content Security and Control Security, Advanced Inspection and Prevention (AIP), or 4 Gigabit Ethernet security. Maximum IPS throughput, depending on the AIP Security Services Module used, can be up to 300 Mbps on the ASA 5510, 450 Mbps on the ASA 5520, and 650 Mbps on the ASA 5540.

Cisco ASA 5550 Firewalls
Cisco ASA 5550 Consulting FirmCisco's ASA 5550 firewall is designed for large enterprises and delivers top firewall throughput of 1,200 Mbps. The ASA 5550 can handle up to 5,000 SSL VPN sessions and 650,000 connections. The Cisco ASA 5550 includes 4 GB of memory and supports up to 250 VLANs. GTP/GPRS inspection, VPN clustering, load balancing, and high availability support are included.

The ASA 5550 does not have expansion slots but has four integrated small form pluggable (SFP) fiber optic Ethernet ports.

Cisco ASA 5580 Firewalls
Cisco ASA 5550 Firewall ConsultingCisco's ASA 5580-20 and 5580-40 firewalls are designed for large enterprise data centers. The ASA 5580-20 has firewall throughput of 5 Gbps, supports 1,000,000 connections, and has 8 GB of memory. The ASA 5580-40 has firewall throughput of 10 Gbps, supports 2,000,000 connections, and has 12 GB of memory. Both versions can handle up to 10,000 SSL VPN sessions and support up to 250 VLANs. Both models include GTP/GPRS inspection, VPN clustering, load balancing, and high availability support, and both have six slots for Interface Expansion Cards (IECs) that allow the addition of Ethernet ports.

Cisco PIX Security Appliance Series
Built on a proven, purpose-built operating system that offers a wealth of security services, PIX firewalls offer a high level of protection and have earned Common Criteria Evaluation Assurance Level 4 status and ICSA Firewall and IPSec certification. PIX firewalls provide security for a wide range of VoIP and other mixed-media protocols including H.323 v. 4, Session Initiation Protocol (SIP), Cisco Skinny Client Control Protocol, Real-Time Streaming Protocol (RTSP), and MGCP. This enables businesses to provide security for a wide range of current and future IP voice and video applications.

PIX Firewalls Consulting Firm
PIX firewalls feature a variety of configuration, monitoring, and troubleshooting features, providing businesses the versatility to use the tools that best meet their needs. Management solutions include common, policy-based administration utilities, integrated Web-based administration, and compatibility with remote-monitoring protocols such as SNMP and syslog. The integrated ASDM interface provides a world-class web-accessible management solution that greatly simplifies the deployment, updating, and monitoring of individual PIX firewalls without requiring any extra software other than an ordinary browser and Java applet to be running on a manager's computer.

IT managers can also remotely configure, track, and troubleshoot PIX firewalls using a command-line interface. Secure command-line interface communication is available using a number of methods such as SSHv2 Protocol, Telnet through IP Security (IPSec), and out-of-band via a console port. Cisco PIX security appliances also have robust automatic-update capabilities, a collection of advanced secure remote-management services that ensure firewall settings and software images are always current.

Progent's PIX to ASA Migration Support
Because Cisco has stopped offering the PIX product line, many businesses are concerned about relying on a critical infrastructure component that may no longer be supported. ASA 5500 firewalls have the advantage of being current products and also offer a number of technical and economic benefits in comparison to PIX devices. These benefits include higher throughput, optional SSL VPN support, and a modular architecture that protects your investment by allowing you to self-install new security services when and if you need them. Progent's Cisco experts can help you determine the business case for migrating from PIX to ASA 5500 firewalls, create a migration plan that allows for a fast and seamless upgrade, help you deploy and configure new ASA 5500 Series appliances, and provide remote training, consulting, and troubleshooting services.

Additional Ways Progent Can Help You with Cisco ASA and PIX Firewalls
Cisco ASA 5500 Series and PIX 500 family firewalls incorporate a broad array of configuration, monitoring, and analysis options that offer you the ability to set up these security appliances to match your company's specific requirements. Progent's CCIE authorized network engineers can help you to design an efficient network infrastructure that includes Cisco ASA and/or PIX security appliances and that offers world-class security, resilience, throughput, and manageability. Progent's GISA and CISSP-ISSP-qualified information security professionals can help you to create a security policy appropriate for your environment and can configure your security appliance to support your security policies. Progent's security evaluation consultants can assess the strength of your current firewall solution and validate the overall security of your entire IT environment. Progent’s Technical Response Center can provide emergency online technical support for Cisco products and can give you quick access to a Cisco CCIE network engineer.

For more details concerning Progent's professional assistance for Cisco solutions, select a topic:

Integration of Cisco and Third-party Security Technology
Progent offers expertise in firewall and VPN products from all major vendors and can help you integrate Cisco technology with additional security solutions to help you build a cost-effective network infrastructure that provides a level of security and flexibility appropriate for your business. Third-party firewall and VPN support services available from Progent include:

To ask Progent about consulting help with Cisco ASA and PIX firewalls, call 1-800-993-9400 or e-mail cisco-help@progent.com.
















© 2002-2013 Progent Corporation. All rights reserved.

More topics of interest: